Agent skill

Harness Oia Audit

by ruvnet in ruvnet/ruflo

Composite Phase-2 audit worker (ADR-150). An agent skill from ruvnet/ruflo.

MITAuto-check: notesProductivity & Automation

Install Harness Oia Audit

skills CLI
$ npx skills add ruvnet/ruflo --skill harness-oia-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/ruflo harness-oia-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/ruflo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ruflo-metaharness/skills/harness-oia-audit .claude/skills/harness-oia-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
harness-oia-audit
GitHub stars
74k
Token cost
~720 tokens
SKILL.md length
219 words
Files
1
Skills in repo
265
Repo updated
First seen
Licence
MIT

At a glance

Composite Phase-2 audit worker (ADR-150). An agent skill from ruvnet/ruflo.

  • Works in 6 steps: Run harness oia-manifest — Open… → Run harness threat-model — categorized… → Run harness mcp-scan — per-server/tool… → …
  • Tasks that involve Scheduled and recurring tasks
  • SKILL.md covers Algorithm, Graceful degradation, CI / cron integration and Memory namespace, plus 1 more section
  • Calls npx

What it does

Harness Oia Audit is an agent skill from ruvnet/ruflo. Composite Phase-2 audit worker (ADR-150). Bundles harness oia-manifest + threat-model + mcp-scan into one timestamped audit record stored in the metaharness-audit memory namespace. Designed for cron-scheduled drift detection.

Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Scheduled and recurring tasks, Threat modeling and Architecture decision records. It works with Model Context Protocol. The repository describes itself as: 🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory…. The licence is MIT.

When your agent uses it

  • Tasks that involve Scheduled and recurring tasks
  • Tasks that involve Threat modeling
  • Tasks that involve Architecture decision records

Example prompts

  • “/harness-oia-audit”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Run harness oia-manifest — Open Infrastructure Architecture
  2. Run harness threat-model — categorized MCP-surface threat
  3. Run harness mcp-scan — per-server/tool policy + permissions
  4. Composite worst = max(threatModel.worst, max(mcpScan.findings.severity)).
  5. Persist payload to memory namespace metaharness-audit with key
  6. alert-on-worst : exit 1 if composite worst ≥ threshold.

What it can do on your machine

Read from SKILL.md and the folder at commit 6c04654. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Harness Oia Audit loads about 720 tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 219 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~720

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/ruflo at commit 6c04654, republished under its MIT licence (© ruvnet). 219 words, ~720 tokens.

Download SKILL.mdSave it as .claude/skills/harness-oia-audit/SKILL.md (or your agent's skills folder).
name
harness-oia-audit
description
Composite Phase-2 audit worker (ADR-150). Bundles harness oia-manifest + threat-model + mcp-scan into one timestamped audit record stored in the `metaharness-audit` memory namespace. Designed for cron-scheduled drift detection.
allowed-tools
Bash
argument-hint
[--path .] [--dry-run] [--alert-on-worst clean|low|medium|high] [--format table|json]

The 13th worker (ADR-150 Phase 2) — runs three MetaHarness static surfaces in one shot, computes a composite worst-severity signal, and persists the audit record to memory so drift over time is visible.

Algorithm

Implementation: scripts/oia-audit.mjs.

  1. Run harness oia-manifest <path> — Open Infrastructure Architecture layer alignment (L1-L9).
  2. Run harness threat-model <path> — categorized MCP-surface threat report with worst: clean|low|medium|high.
  3. Run harness mcp-scan <path> — per-server/tool policy + permissions
    • dep findings.
  4. Composite worst = max(threatModel.worst, max(mcpScan.findings.severity)).
  5. Persist payload to memory namespace metaharness-audit with key audit-<iso-timestamp> (unless --dry-run).
  6. --alert-on-worst <severity>: exit 1 if composite worst ≥ threshold.

Graceful degradation

When ALL three components report metaharness-not-available, the script emits the standard degraded payload and exits 0. When only some are degraded, each individual component carries its own degraded: true flag in the audit record — the audit still runs and persists what it could gather.

CI / cron integration

Designed for weekly cron in .github/workflows/:

yaml
on:
  schedule:
    - cron: '17 4 * * 0'  # Sundays at 04:17 UTC
jobs:
  oia-audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
      - run: node plugins/ruflo-metaharness/scripts/oia-audit.mjs --alert-on-worst high

--alert-on-worst high fails the job on any HIGH-severity finding; drift below HIGH is logged but doesn't block.

Memory namespace

Each audit run stores under metaharness-audit:audit-<iso-ts>. To list recent audits:

bash
npx @claude-flow/cli@latest memory list --namespace metaharness-audit --limit 10

To diff two audits (drift detection):

bash
A=$(npx ... memory retrieve --key audit-2026-06-01... --namespace metaharness-audit)
B=$(npx ... memory retrieve --key audit-2026-06-15... --namespace metaharness-audit)
# Compare composite.worst, components.threatModel.worst, etc.

A future ADR can wire this into a dedicated cost-diff-style diff viewer specifically for audit drift.

Pairs with

  • harness-threat-model — the underlying threat-model component
  • harness-mcp-scan — the underlying MCP-scan component
  • harness-score + harness-genome — readiness metrics (orthogonal to audit)

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ruflo-metaharness/skills/harness-oia-audit of ruvnet/ruflo.

Open the folder on GitHubat commit 6c04654

Compare with similar skills

Harness Oia Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Harness Oia Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Harness Oia Audit this skillruvnet/ruflo74k—~720Automated safety check: NotesMIT
Securitytelagod/code-abyss244—~907Automated safety check: PassMIT
Bumblebee Hygiene ScanSzotasz/marveen117—~2.1kAutomated safety check: PassMIT
Codex Chatgpt BridgeZhenyu98/codex-chatgpt-bridge278—~4kAutomated safety check: PassMIT
Scrapingbee CLIScrapingBee/scrapingbee-cli108—~3.2kAutomated safety check: NotesMIT
Threat Modelruvnet/metaharness696—~637Automated safety check: NotesMIT

Similar skills

  • Security

    telagod/code-abyss

    Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

    244 GitHub stars~907 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Bumblebee Hygiene Scan

    Szotasz/marveen

    Weekly supply-chain hygiene scan (Perplexity Bumblebee). An agent skill from Szotasz/marveen.

    117 GitHub stars~2.1k tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Codex Chatgpt Bridge

    Zhenyu98/codex-chatgpt-bridge

    A skill your agent uses when Codex needs to coordinate ChatGPT, Chrome, Cloudflare tunnels, verified bridge Restart/Reboot recovery, or task routing between local code execution and ChatGPT…

    278 GitHub stars~4k tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check passed
  • Scrapingbee CLI

    ScrapingBee/scrapingbee-cli

    Fetch and read any web page, search the web, crawl a site, or pull structured data out of pages.

    108 GitHub stars~3.2k tokensUpdated 3 days ago
    Productivity & AutomationAuto-check: notes
  • Threat Model

    ruvnet/metaharness

    MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness.

    696 GitHub stars~637 tokensUpdated yesterday
    SecurityAuto-check: notes
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    532 GitHub stars~3.3k tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check passed

More from ruvnet/ruflo

All 265 skills in this repo
  • Stores, searches, and retrieves successful patterns with HNSW-indexed semantic search so agents can reuse past solutions instead of relearning them.

    74k GitHub starsUsed in 1 repo~830 tokens
    Auto-check passed
  • Sets up and drives Ruflo, an npm-installed orchestration layer for multi-agent swarms, persistent memory, routing, hooks and its MCP tool catalog.

    74k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    Auto-check passed
  • Applies the SPARC method (specification, pseudocode, architecture, refinement, completion) with 17 specialized modes and multi-agent orchestration, from research to deployment.

    74k GitHub starsUsed in 1 repo~829 tokens
    Auto-check passed
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 1 repo~779 tokens
    Auto-check passed
  • Finds models on the Hugging Face router that lack descriptions in chat-ui's prod.yaml and dev.yaml, researches each one and adds short descriptions.

    74k GitHub starsUsed in 1 repo~600 tokens
    Auto-check passed

Questions about Harness Oia Audit

What does Harness Oia Audit do?

Composite Phase-2 audit worker (ADR-150). An agent skill from ruvnet/ruflo. Harness Oia Audit is an agent skill from ruvnet/ruflo. Composite Phase-2 audit worker (ADR-150).

When should I use Harness Oia Audit?

Harness Oia Audit fits situations like: tasks that involve Scheduled and recurring tasks; tasks that involve Threat modeling; tasks that involve Architecture decision records.

How do I install Harness Oia Audit in Claude Code?

Run `npx skills add ruvnet/ruflo --skill harness-oia-audit -a claude-code`. Or copy the skill folder (plugins/ruflo-metaharness/skills/harness-oia-audit in ruvnet/ruflo) into .claude/skills/harness-oia-audit in your project. Claude Code loads it when a task matches its description.

How do I install Harness Oia Audit in Codex?

Run `npx skills add ruvnet/ruflo --skill harness-oia-audit -a codex`. Or copy the skill folder (plugins/ruflo-metaharness/skills/harness-oia-audit in ruvnet/ruflo) into .agents/skills/harness-oia-audit in your project. Codex loads it when a task matches its description.

Can I use Harness Oia Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/ruflo --skill harness-oia-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harness-oia-audit, .gemini/skills/harness-oia-audit, .github/skills/harness-oia-audit and .opencode/skills/harness-oia-audit in your project.

What does Harness Oia Audit need to run?

Going by SKILL.md and its folder, Harness Oia Audit needs the command-line tools its instructions call (npx). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash.

Does Harness Oia Audit access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Harness Oia Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Harness Oia Audit use?

Harness Oia Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Harness Oia Audit use?

About 720 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Harness Oia Audit?

Skills that share tags, products or a category with Harness Oia Audit: Security (telagod/code-abyss, 244 stars), Bumblebee Hygiene Scan (Szotasz/marveen, 117 stars), Codex Chatgpt Bridge (Zhenyu98/codex-chatgpt-bridge, 278 stars) and Scrapingbee CLI (ScrapingBee/scrapingbee-cli, 108 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Harness Oia Audit?

ruvnet (a GitHub user) maintains it in ruvnet/ruflo, which has 74,222 GitHub stars. The repository holds 265 skills in this directory. The repository was last updated on October 10, 2026.

Source: ruvnet/ruflo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.